Burner Control
hard
Burner control state machine through Purge, Ignite, Run, and Lockout states with safety inputs.
What it teaches
Safety-critical state machine: every transition has prerequisites that, if violated, drop to Lockout. Lockout requires manual reset. Teaches that not all faults clear themselves — some require explicit operator acknowledgment for safety.
Inputs and outputs
| Tag | Type | Default | Description |
|---|---|---|---|
| In_Run | BOOL | — | Call for heat; 1 requests the burner, 0 stops it |
| In_Reset | BOOL | — | Manual reset push button for Lockout |
| In_Permissive | BOOL | — | Boiler interlocks satisfied; the Sts_Permissive output of Boiler Interlocks |
| In_AirFlow | BOOL | — | Combustion air proven by the air flow switch |
| In_Flame | BOOL | — | Flame detected by the flame scanner |
| Cfg_PurgeTime | DINT | 4000 | Purge duration in milliseconds |
| Cfg_IgniteTime | DINT | 2000 | Time allowed for flame to appear after the fuel valve opens, in milliseconds |
| Out_Blower | BOOL | — | Combustion air blower |
| Out_Ignitor | BOOL | — | Spark ignitor |
| Out_FuelValve | BOOL | — | Main fuel valve |
| Sts_State | DINT | — | 0=Idle, 1=Purge, 2=Ignite, 3=Run, 4=Lockout |
Required behavior
- Cfg_PurgeTime and Cfg_IgniteTime must be 0 or greater.
- In Idle every output is 0. Idle moves to Purge only while In_Run and In_Permissive are both 1. A call for heat without the permissive waits in Idle.
- Purge runs Out_Blower alone for Cfg_PurgeTime, then moves to Ignite.
- Ignite turns on Out_Blower, Out_Ignitor and Out_FuelValve. The first scan that sees In_Flame at 1 moves to Run. If Cfg_IgniteTime passes with no flame, the burner drops to Lockout. If the flame arrives on the same scan that Cfg_IgniteTime runs out, either Run or Lockout is acceptable.
- Run keeps Out_Blower and Out_FuelValve on and turns Out_Ignitor off. Run has no time limit. If In_Flame drops to 0, the burner drops to Lockout.
- Purge, Ignite and Run all require In_AirFlow and In_Permissive at 1. Losing either drops to Lockout. A start without air proven goes to Lockout; whether Out_Blower pulses for one scan on the way is implementation-dependent.
- A flame during Purge is a fault. In_Flame at 1 while purging drops to Lockout.
- Lockout turns every output off and holds Sts_State at 4. Air, flame or the permissive returning does not clear it, and neither does dropping In_Run. Only a new press of In_Reset clears it, returning to Idle.
- A reset already held when the lockout happens does not count. Release and press again.
- In_Run dropping to 0 in Purge, Ignite or Run returns to Idle with no lockout. Every restart begins with a full Purge, including the restart after a reset.
- A fault and a stop in the same scan: the fault wins and the burner locks out.
- In_Reset has no effect outside Lockout.